# @semantic-release/github@12.0.5 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-06T14:12:21.000Z
- Files reviewed: 21
- Findings: 2 medium, 6 low severity findings
- Report: https://security.togoder.click/npm/@semantic-release/github
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package @semantic-release/github@12.0.5 on Oct 6, 2026. An AI review of 21 source files produced 2 medium, 6 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Import-time side effects

Finding ID: `NPS-37E164D3FAA9`

File: `index.js`

The module maintains a module-level mutable state variable 'verified' that is set during verifyConditions and used across publish/addChannel/success/fail. While this file itself does not execute network or filesystem operations at import time, the imported modules (./lib/verify.js, ./lib/publish.js, ./lib/add-channel.js, ./lib/success.js, ./lib/fail.js, ./lib/octokit.js) are not shown and could contain hidden side effects or malicious logic (credential harvesting, exfiltration, etc.). The code should be reviewed alongside those files.

### [medium] GitHub token / credential access via Octokit

Finding ID: `NPS-CBAD3C3D311A`

File: `index.js`

The plugin conditionally injects an Octokit instance (SemanticReleaseOctokit) and passes it to verify/publish/addChannel/success/fail functions. Octokit instances typically carry GitHub authentication tokens (GH_TOKEN/GITHUB_TOKEN) from the environment. Because the downstream lib files are not provided, there is no visibility into whether these tokens are used only for intended GitHub API calls or potentially exfiltrated. This is a common vector for supply-chain token theft in CI/CD environments.

### [low] Configuration merge from other plugin configs

Finding ID: `NPS-680692133F80`

File: `index.js:22`

The verifyConditions function reads the 'publish' plugin configuration and copies fields (assets, successComment, failComment, failTitle, labels, assignees, discussionCategoryName) into pluginConfig. While this mirrors legitimate @semantic-release/github behavior, it allows one plugin's config to influence another's behavior, which could be abused in a compromised dependency chain to inject attacker-controlled values (e.g., labels, comments) into GitHub releases. This is not inherently malicious but warrants scrutiny in context.

### [low] Dynamic module loading via createRequire

Finding ID: `NPS-5004A9F46138`

File: `lib/octokit.js:22`

Uses createRequire(import.meta.url) to load package.json at import time. While package.json is loaded from a relative path, createRequire enables arbitrary module resolution and loading which could be abused if the path were influenced. This pattern is common but worth noting.

### [low] Top-level code execution on import

Finding ID: `NPS-9D1F87AD4614`

File: `lib/octokit.js:24`

Top-level statements read package.json and construct the Octokit plugin class at module load time. This is benign initialization but does execute on import.

### [low] Proxy agent configuration with user input

Finding ID: `NPS-3F4054FB5CD2`

File: `lib/octokit.js:73`

Proxy agents (HttpProxyAgent, HttpsProxyAgent, ProxyAgent) are constructed from the options.proxy value passed by the caller. If options.proxy is attacker-controlled, requests could be redirected through arbitrary proxies, enabling MITM or data exfiltration. This is a legitimate feature for the package but requires the caller to validate proxy config.

### [low] Network requests with dynamic URLs

Finding ID: `NPS-9D7D88BF439D`

File: `lib/octokit.js:78`

fetchWithDispatcher sends HTTP requests to caller-supplied URLs (baseUrl / githubApiUrl). This is expected functionality of a GitHub API client, but the dynamic URL construction via urljoin could allow requests to unintended hosts if inputs are attacker-controlled.

### [low] unknown

Finding ID: `NPS-D97596670BD0`

File: `lib/resolve-config.js:25`

The function reads sensitive environment variables such as GH_TOKEN, GITHUB_TOKEN and proxy settings. Although this is normal for a config resolver, it could be abused if the resolved config is later logged or sent elsewhere. No exfiltration is present in this file.

## Files reviewed

- `index.js` (medium): This file is the public entry point for what appears to be @semantic-release/github; no direct malicious patterns are present, but it delegates sensitive operations (GitHub API calls with auth tokens) to unreviewed lib/* modules and merges configuration from other plugin configs, so downstream files must be audited to rule out credential exfiltration or supply-chain abuse.
- `lib/octokit.js` (medium): This is a legitimate GitHub API client wrapper (@semantic-release/github) with no obvious malicious patterns; minor concerns relate to dynamic require, proxy handling, and import-time initialization, all consistent with its intended purpose.
- `lib/resolve-config.js` (medium): No malicious patterns detected; the file is a normal configuration resolver that reads environment variables but does not exfiltrate or execute untrusted code.
- `lib/add-channel.js` (safe): No malicious patterns detected; the code is a legitimate semantic-release GitHub plugin that creates or updates GitHub releases using configured credentials.
- `lib/definitions/constants.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/definitions/errors.js` (safe): No malicious patterns detected; the file contains only error message definitions for a semantic-release plugin, using standard Node.js utilities with no network, credential, or process manipulation.
- `lib/definitions/retry.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/definitions/throttle.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/fail.js` (safe): No malicious patterns detected; the code is a legitimate semantic-release GitHub plugin that creates issues on release failure.
- `lib/find-sr-issues.js` (safe): No malicious patterns detected
- `lib/get-error.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/get-fail-comment.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/get-release-links.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/get-success-comment.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/glob-assets.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/is-latest-release.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/is-prerelease.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/parse-github-url.js` (safe): No malicious patterns detected
- `lib/publish.js` (safe): No malicious patterns detected; this is a legitimate semantic-release GitHub plugin that publishes releases and uploads assets via the GitHub API.
- `lib/success.js` (safe): No malicious patterns detected; the file is a standard semantic-release GitHub plugin that uses the provided Octokit instance for GitHub API calls and contains no exfiltration, credential harvesting, obfuscation, or shell execution.
- `lib/verify.js` (safe): No malicious patterns detected; the file contains legitimate configuration validation and GitHub API verification logic for a semantic-release plugin.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
